CVE-2015-5162

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:cinder:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:cinder:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:cinder:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:13.0.0:*:*:*:*:*:*:*

History

13 Feb 2023, 00:50

Type Values Removed Values Added
Summary A resource vulnerability in the OpenStack Compute (nova), Block Storage (cinder), and Image (glance) services was found in their use of qemu-img. An unprivileged user could consume as much as 4 GB of RAM on the compute host by uploading a malicious image. This flaw could lead possibly to host out-of-memory errors and negatively affect other running tenant instances. oslo.concurrency has been updated to support process limits ('prlimit'), which is needed to fix this flaw. The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2017:0165', 'name': 'https://access.redhat.com/errata/RHSA-2017:0165', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2017:0282', 'name': 'https://access.redhat.com/errata/RHSA-2017:0282', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2016:2923', 'name': 'https://access.redhat.com/errata/RHSA-2016:2923', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1268303', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1268303', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-5162', 'name': 'https://access.redhat.com/security/cve/CVE-2015-5162', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2016:2991', 'name': 'https://access.redhat.com/errata/RHSA-2016:2991', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2017:0153', 'name': 'https://access.redhat.com/errata/RHSA-2017:0153', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2017:0156', 'name': 'https://access.redhat.com/errata/RHSA-2017:0156', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2017:0165 -
  • (MISC) https://access.redhat.com/errata/RHSA-2017:0282 -
  • (MISC) https://access.redhat.com/errata/RHSA-2016:2923 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1268303 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-5162 -
  • (MISC) https://access.redhat.com/errata/RHSA-2016:2991 -
  • (MISC) https://access.redhat.com/errata/RHSA-2017:0153 -
  • (MISC) https://access.redhat.com/errata/RHSA-2017:0156 -
Summary The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. A resource vulnerability in the OpenStack Compute (nova), Block Storage (cinder), and Image (glance) services was found in their use of qemu-img. An unprivileged user could consume as much as 4 GB of RAM on the compute host by uploading a malicious image. This flaw could lead possibly to host out-of-memory errors and negatively affect other running tenant instances. oslo.concurrency has been updated to support process limits ('prlimit'), which is needed to fix this flaw.

Information

Published : 2016-10-07 14:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-5162

Mitre link : CVE-2015-5162

CVE.ORG link : CVE-2015-5162


JSON object : View

Products Affected

openstack

  • nova
  • cinder
  • glance
CWE
CWE-399

Resource Management Errors